Skip to content
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure

Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure

First seen 11 Sep 2026, 12:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 22:47 UTC
  • CVE-2026-85706 allows unauthenticated file read access, rated CVSS 10.0.
  • CVE-2026-87719 enables credential theft for authenticated users, rated CVSS 9.9.
  • Active exploitation attempts were reported just one day after the vulnerabilities were disclosed.

On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 up to 19.3.2. Just one day after the patches were released, threat intelligence firm WatchTowr reported active exploitation attempts targeting CVE-2026-85706. Organizations running self-managed GitLab instances are urged to upgrade immediately, as the vulnerabilities can expose sensitive data and configurations. The situation is critical, with the potential for widespread exploitation expected soon.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-06-11
CVE-2021-22175 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-13
CVE-2021-39935 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-05-25
Public exploit for CVE-2023-2825 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-01-13
CVE-2025-25249 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-04
CVE-2026-20079 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-17
CVE-2026-19478 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-19949 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-85102 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-85103 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (18)

Following this threat?

Track NoviSpy and CVE-2021-22175 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed